

James Wong
Polestar simplifying options as it aims to improve value for money
39 Minutes Ago

Deputy News Editor
Toyota Australia has confirmed highly sensitive customer data is encrypted and never transmitted from its vehicles, following recent calls for greater government regulation of information generated by ‘connected vehicles’.
A recent investigation by ABC program Four Corners raised concerns over data security and the potential for connected vehicles to be hacked, with BYD, Xpeng and Leapmotor vehicles featuring in its report.
The term ‘connected car’ refers to vehicles connected to the internet, enabling functions such as over-the-air software updates, but also providing automakers with unprecedented access to information including vehicle location and customer driving behaviour.
Toyota Australia said at a recent business update at its Port Melbourne headquarters that there are now more than one million connected Toyotas on Australian roads, after it launched Toyota Connected Services in November 2020.

Almost every model across Toyota Australia’s current passenger and commercial vehicle range offers Toyota Connected Services, with the LandCruiser 70 Series, GR86 sports car and Tundra full-size pickup among the exceptions.
Speaking to CarExpert, John Pappas, Toyota Australia vice president of sales, marketing and franchise operations, said the automaker is extremely diligent when it comes to handling data, with customer privacy a priority.
“Our data systems are hosted in secure data centres, the majority of which are located in Australia, with some data also processed and stored in secure Toyota-managed environments in North America and Singapore,” Mr Pappas explained.
“What’s most important for us is with Toyota vehicles, we look at safety of protection and safety of our customers’ data and their privacy, the same as we do when we look at safety of our vehicle. For us, we call it hardware equals software.

“What’s most important is that the data, the customer data, and privacy is highly governed with Toyota, highly governed.”
Asked whether a Toyota vehicle could be hacked, and what protections Toyota Australia vehicles have, Mr Pappas reiterated the automaker’s use of data encryption.
“Hacking protections, for other brands, I really can’t comment,” Mr Pappas said.
“I can't comment on any other brand because I don’t know what they do; that’s their call, but what I do know is about Toyota, and it’s highly governed, the data and the privacy side. Any highly sensitive data is fully encrypted inside the car, is never transmitted.”

Toyota is currently the subject of an ongoing investigation by the Office of the Australian Information Commissioner (OAIC), which is also investigating Hyundai over connected-vehicle privacy.
The OAIC hasn't publicly detailed its investigation, nor announced any findings of wrongdoing by either Toyota or Hyundai. It began preliminary inquiries into connected-car privacy in February 2024, but the vehicle brands involved were not made public until 2026.
Toyota updated its Connected Services Privacy Policy in March 2026, with the current policy stating that, outside specified circumstances, Toyota doesn't share information about a customer’s use of Connected Services with anyone else unless the customer asks it to.
It also states that personal information collected through Connected Services isn't used for direct marketing.

For example, SOS Emergency Call – which forms part of ANCAP’s 2026 assessment protocols and is included by Toyota free for the life of the relevant mobile network – can transmit information required to provide emergency assistance.
Toyota says the service has already been used more than 10,000 times in Australia.
Stolen Vehicle Tracking data may similarly be provided to police. Toyota models including the RAV4 SUV, HiLux ute and LandCruiser 300 Series have been among vehicles targeted during a rise in vehicle thefts in Australia, including in Victoria, where thefts have reached two-decade highs.

BYD also changed its privacy policy, as noted by Four Corners in the episode aired on September 21, 2026. The program reported the revised policy removed previous references to 16 countries to which customer data could be sent.
The automaker launched an investigation into the program’s findings and subsequently said it would implement software changes, “thereby eliminating the access path identified during the investigation”.
Canberra-based Fortify Labs, which carried out the vehicle ‘attacks’ for Four Corners, said on its website it hoped the program would be a catalyst for change. It suggested introducing a cyber-security star rating to allow customers to compare the level of protection offered by different brands.
Research cars in our Showroom, compare your options or let our New Car Specialists do the running around to find you a great deal.
Damion Smy is an award-winning motoring journalist with global editorial experience at Car, Auto Express, and Wheels.


James Wong
39 Minutes Ago


Damion Smy
2 Hours Ago


Damion Smy
3 Hours Ago


William Stopford
3 Hours Ago


Damion Smy
5 Hours Ago


Ben Zachariah
13 Hours Ago
Add CarExpert as a Preferred Source on Google so your search results prioritise writing by actual experts, not AI.